The CLOSEDQUORUM implant utilizes a quorum of four large language models to automate post-exploitation decisions on Windows hosts. Rather than querying a central attacker server for instructions, the malware sends system context to DeepSeek, Qwen, Mistral and Gemini. It prompts these models as "advanced malware strategists" and executes the plurality verdict to either steal data, inject code, persist on the machine or move laterally. Cisco Talos identified the malware, which employs browser credential theft, LSASS dumps and crypto wallet extraction for its payloads and exfiltrates data via a Discord webhook. Talos described the tool as early and limited, noting that the discovered sample contains placeholder API keys suggesting it is a per-operator kit rather than a live campaign. Security analysts are advised to monitor endpoints for egress traffic to multiple AI provider APIs from processes accessing sensitive system memory.
Key sources
- SOURCEmarketbrief.now
- SOURCEhuggingnewshuggingnews.com